← Back
CWE-787

14,813 CVEs • Abstraction: Base • Likelihood of Exploit: High

Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

JSON object

Loading...

CVEs (14,813)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mikrotik
1Routeros
Jun 17, 2026
Jul 21, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
2Artifex
Debian
2Debian Linux
Mupdf
Jun 17, 2026
Jul 21, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service.
1Nvidia
1Virtual Gpu
Jun 17, 2026
Jul 21, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) that could allow an attacker to cause stack-based buffer overflow and put a customized ROP gadget on the stack. Such an attack may le...Show more
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) that could allow an attacker to cause stack-based buffer overflow and put a customized ROP gadget on the stack. Such an attack may lead to information disclosure, data tampering, or denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).Show less
6Debian
FedoraprojectLinux+3 more
7Communications Session Border Controller
Debian LinuxFedora+4 more
Jun 17, 2026
Jul 20, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged use...Show more
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.Show less
3Debian
FedoraprojectLibsndfile Project
3Debian Linux
FedoraLibsndfile
Jun 17, 2026
Jul 20, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.
2Fedoraproject
Unicorn Engine
2Fedora
Unicorn Engine
Jun 17, 2026
Jul 20, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb).
1Qpdf Project
1Qpdf
Jun 17, 2026
Jul 20, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.
1Matio Project
1Matio
Jun 17, 2026
Jul 20, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
matio (aka MAT File I/O Library) 1.5.20 and 1.5.21 has a heap-based buffer overflow in H5MM_memcpy (called from H5MM_malloc and H5C_load_entry), related to use of HDF5 1.12.0.
1Unicorn Engine
1Unicorn Engine
Jun 17, 2026
Jul 20, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Unicorn Engine 1.0.2 has an out-of-bounds write in helper_wfe_arm.
2Fedoraproject
Libass Project
2Fedora
Libass
Jun 17, 2026
Jul 20, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
1Open62541
1Open62541
Jun 17, 2026
Jul 20, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Variant_encodeJson in open62541 1.x before 1.0.4 has an out-of-bounds write for a large recursion depth.
1Matio Project
1Matio
Jun 17, 2026
Jul 20, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
matio (aka MAT File I/O Library) 1.5.18 through 1.5.21 has a heap-based buffer overflow in ReadInt32DataDouble (called from ReadInt32Data and Mat_VarRead4).
3Debian
FedoraprojectGnu
3Aspell
Debian LinuxFedora
Jun 17, 2026
Jul 20, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).
1Osgeo
1Gdal
Jun 17, 2026
Jul 20, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netC...Show more
netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).Show less
1Mikrotik
1Routeros
Jun 17, 2026
Jul 19, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenticated remote attacker can cause a Denial of Service.
1Zohocorp
1Manageengine Assetexplorer
Jun 17, 2026
Jul 19, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send...Show more
Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the agent's HTTP request verifying its authtoken. In AEAgent.cpp, the agent responding back over HTTP is vulnerable to a Heap Overflow if the POST payload response is too large. The POST payload response is converted to Unicode using vswprintf. This is written to a buffer only 0x2000 bytes big. If POST payload is larger, then heap overflow will occur.Show less
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Aug 10, 2026
Jul 16, 2021
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Scripting Engine Memory Corruption Vulnerability
1Ok File Formats Project
1Ok File Formats
Jun 17, 2026
Jul 15, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg f...Show more
A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.Show less
1Ok File Formats Project
1Ok File Formats
Jun 17, 2026
Jul 15, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg...Show more
A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.Show less
1Juniper
1Steel Belted Radius Carrier
Jun 17, 2026
Jul 15, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon t...Show more
A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Service (DoS) or leading to remote code execution (RCE). By continuously sending this specific packets, an attacker can repeatedly crash the radius daemon, causing a sustained Denial of Service (DoS). This issue affects Juniper Networks SBR Carrier: 8.4.1 versions prior to 8.4.1R19; 8.5.0 versions prior to 8.5.0R10; 8.6.0 versions prior to 8.6.0R4.Show less